TLDR
A firmware bug in Coldcard Bitcoin wallets has enabled attackers to drain tens of millions of dollars, with total losses now estimated near $114 million.
- Researchers have confirmed about 1,367 BTC (~$88.6 million) stolen, with a fourth wave of sweeps pushing estimated losses toward 1,816 BTC (~$114 million).
- The flaw came from weak randomness in seed generation on some Coldcard devices, letting attackers guess private keys without touching the hardware or phish users.
- The incident is driving Bitcoin back to exchanges and shaking confidence in self?custody, while regulators, lawyers and users watch to see if losses and legal action escalate further.
Confidence: high on the confirmed 1,367 BTC figure, moderate on the ~$114 million total because the latest wave is still being validated.
Deep Dive
1. Scale Of The Losses
Galaxy Research and multiple outlets report that three confirmed attack waves have drained 1,367.05 BTC, worth about $88.6 million, from roughly 4,585 Coldcard-generated addresses as of 2 August 2026 %%CKPROTECTED0%%.
A fourth, partly pattern-based wave of sweeps has now been identified, bringing the estimated total to about 1,816 BTC, or roughly $114 million, across more than 5,200 addresses Coldcard losses near $114M.
Legal pressure is rising too, with victims reportedly preparing class-action suits against Coldcards manufacturer, Coinkite, over losses exceeding 1,300 BTC Coinkite faces class action threat.
The confirmed loss is already one of the largest hardware-wallet failures ever, and the upper estimate may climb as more affected addresses are mapped.
2. How The Bug Broke Self-Custody
The exploit is not a hack of Bitcoin itself, but a firmware error in Coldcards seed generation that reduced entropy so much that seed phrases became guessable Bitcoin was not hacked.
Firmware released in March 2021 caused some devices to use a software pseudo-random number generator instead of the hardware random source, shrinking effective randomness from the intended 128 bits to about 4072 bits depending on the model Coldcard PRNG vulnerability.
Attackers brute-forced those weak seeds, then swept funds from single-signature Coldcard wallets in multiple coordinated waves; multisig setups have not been affected, and newer patched firmware only secures seeds generated after the fix Coldcard pushes bitcoin back to exchanges.
3. Market And User Reaction
On-chain, small holders reacted quickly: transfers under 1 BTC surged to 39,600 BTC (about $2.5 billion) on 31 July, matching post?FTX panic levels, with sub?10 BTC deposits to exchanges also spiking Coldcard losses near $114M.
Analysts note net flows from self?custody back to exchanges have been positive every day since 31 July, reversing the usual post?FTX trend of moving off exchanges into hardware wallets Coldcard pushes bitcoin back to exchanges.
Despite the size of the loss, Bitcoin and the broader market have only seen modest price pressure so far, with recent coverage describing the drop as restrained relative to the scale of the cold?wallet failure Bitcoin, ether decline as Coldcard exploit enters a fifth day.
The direct hit is on affected Coldcard users and on trust in self?custody tools, more than on Bitcoins protocol or overall market structure, but confidence damage can still weigh on flows and sentiment.
Conclusion
Coldcards firmware bug turned what was marketed as high?security cold storage into a weak-key generator, enabling remote drains of at least $88 million and possibly around $114 million in Bitcoin.
So far the Bitcoin network itself remains secure, and market prices have absorbed the shock, but the episode is pushing many users back toward exchanges and forcing a rethink of how much trust to place in any single hardware wallet or seed-generation method.
